Recital 6

Recital 6

Digital Operational Resilience Act · UE 2022/2554

(6)

In its Communication of 8 March 2018 entitled ‘FinTech Action plan: For a more competitive and innovative European financial sector’, the Commission highlighted the paramount importance of making the Union financial sector more resilient, including from an operational perspective to ensure its technological safety and good functioning, its quick recovery from ICT breaches and incidents, ultimately enabling the effective and smooth provision of financial services across the whole Union, including under situations of stress, while also preserving consumer and market trust and confidence.

Luxembourg specificity
Circulaire CSSF 24/847 sur la notification des incidents TIC et la circulaire CSSF 22/806 sur les arrangements d'externalisation TIC

In Luxembourg, the CSSF is the designated competent authority for DORA and has published CSSF Circular 24/847 detailing major ICT incident notification, along with its integration with the TIBER-LU framework run by the BCL for threat-led penetration testing. Luxembourg financial sector entities (banks, PFS, funds, insurers) must also articulate DORA with CSSF Circular 22/806 on ICT outsourcing arrangements.

Luxgap practice: we calibrate our recovery tests on the critical services identified by the CSSF in its annual ICT resilience survey, and we produce deliverables in the format expected by the CSSF SuRO unit.